Alle Tags
Katalog-Tag

#supply-chain-security

Alle Repositories im öffentlichen Register, die dieses Tag tragen — aus ihren GitHub-Topics oder den von ihren Paket-Registries veröffentlichten Schlagwörtern. Die Gesundheit wird nach derselben versionierten Methodik gemessen wie im übrigen Register.

33 Einträge
Getaggt als „supply-chain-security“Geordnet nach Gesundheitsindex
Go
85ExzellentGesundheitsindex
chainloop-dev/chainloop
SDLC evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more
Go★ 57016. Juli 2026
Apache-2.016. Juli 2026 · Metriken 1.13.0
PyPI · npm
80GutGesundheitsindex
msaad00/agent-bom
Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings, govern in your VPC.
Python · TypeScript★ 28↓ 5.301/Monat16. Juli 2026
Apache-2.016. Juli 2026 · Metriken 1.13.0
npm
77GutGesundheitsindex
lirantal/npq
safely install npm packages by auditing them pre-install stage
JavaScript★ 1.759↓ 35.4K/Monat17. Juli 2026
Apache-2.017. Juli 2026 · Metriken 1.13.0
Go · npm
77GutGesundheitsindex
safedep/pmg
PMG protects developers, AI agents from malicious open source packages using proxy, sandbox and SafeDep's threat intelligence feed.
Go★ 46417. Juli 2026
Apache-2.017. Juli 2026 · Metriken 1.13.0
Go
76GutGesundheitsindex
carabiner-dev/ampel
🔴🟡🟢 The Amazing Multipurpose Policy Engine (and L)
Go★ 5421. Juli 2026
Apache-2.021. Juli 2026 · Metriken 1.13.0
crates.io
75GutGesundheitsindex
always-further/nono
Sandbox any AI agent in seconds - zero setup, zero latency.
Rust★ 3.03617. Juli 2026
Apache-2.017. Juli 2026 · Metriken 1.13.0
crates.io
75GutGesundheitsindex
lukehinds/nono
Sandbox any AI agent in seconds - zero setup, zero latency.
Rust★ 3.04719. Juli 2026
Apache-2.019. Juli 2026 · Metriken 1.13.0
crates.io
74GutGesundheitsindex
nolabs-ai/nono
Sandbox any AI agent in seconds - zero setup, zero latency.
Rust★ 3.01616. Juli 2026
Apache-2.016. Juli 2026 · Metriken 1.13.0
npm · PyPI
71GutGesundheitsindex
DNSZLSK/muad-dib
Real-time npm/PyPI supply-chain threat detection. Behavioral chain analysis, AST scanning, IOC feeds, and compound scoring engine.
JavaScript★ 15↓ 14.1K/Monat14. Juli 2026
AGPL-3.014. Juli 2026 · Metriken 1.13.0
Go · PyPI
71GutGesundheitsindex
bomly-dev/bomly-cli
Free, open-source CLI for dependency intelligence, SBOMs, vulnerability auditing, and CI policy gates.
Go★ 917. Juli 2026
Apache-2.017. Juli 2026 · Metriken 1.13.0
Go · PyPI
71GutGesundheitsindex
felixgeelhaar/mnemos
Self-hosted memory + evidence layer for AI agents (Claude Code, Codex, Hermes, ...) — embeddable Go library, MCP / HTTP / CLI, evidence-backed claims, bitemporal recall, axi-go execution kernel with JSONL audit + token budgets, cosign-signed releases with SLSA L3 provenance. No vendor cloud, no per-call billing.
Go★ 316. Juli 2026
MIT16. Juli 2026 · Metriken 1.13.0
Go
71GutGesundheitsindex
sisaku-security/sisakulint
CI-Friendly static linter with autofix, SAST, semantic analysis for GitHub Actions
Go★ 4219. Juli 2026
Apache-2.019. Juli 2026 · Metriken 1.13.0
PyPI · npm
70GutGesundheitsindex
hashgraph-online/hol-guard
Open-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, MCP servers, plugins, and skills at runtime.
Python · TypeScript · JavaScript★ 39615. Juli 2026
Eigene Lizenz15. Juli 2026 · Metriken 1.13.0
Go
68MittelGesundheitsindex
airomhq/airom
Open-source AI Bill of Materials (AIBOM) scanner: inventories AI models, datasets, prompts, embeddings, vector DBs & RAG pipelines across code, containers & Kubernetes — with file:line evidence, load-time risk detection (poisoned pickle / Keras Lambda / unsafe torch.load) and NIST AI RMF / OWASP compliance mapping. CycloneDX · SARIF · JSON.
Go · MDX★ 823. Juli 2026
Apache-2.023. Juli 2026 · Metriken 1.13.0
PyPI
68MittelGesundheitsindex
cpeoples/ansible-security-scanner
🛡️ Static security scanner (SAST) for Ansible playbooks, roles, and collections. 1,000+ rules across 30+ categories detecting malicious code, RCE, hardcoded credentials, and supply-chain risk. Outputs SARIF, CycloneDX SBOM, and GitLab SAST. SLSA Build Level 3, Sigstore-signed.
Python★ 9↓ 1.928/Monat17. Juli 2026
Apache-2.017. Juli 2026 · Metriken 1.13.0
Go
67MittelGesundheitsindex
rezmoss/sbomlyze
git diff for your SBOM ,compare CycloneDX/SPDX/Syft bills of materials, detect tampering, and gate CI
Go★ 2420. Juli 2026
Apache-2.020. Juli 2026 · Metriken 1.13.0
PyPI
67MittelGesundheitsindex
squid-protocol/gitgalaxy
Deep repository intelligence for humans and ai. Air gapped, on premise, zero dependency SAST for 50 languages regardless of compilation status. Sarif and sbom outputs.
Python★ 45↓ 0/Monat14. Juli 2026
Eigene Lizenz14. Juli 2026 · Metriken 1.13.0
Go
65MittelGesundheitsindex
draugr-dev/draugr
Developer-first security scanning orchestration — describe your app in one file, run many scanners (SAST, SCA, secrets, IaC, containers, headers), get one SARIF verdict for CI & code scanning.
Go★ 019. Juli 2026
Apache-2.019. Juli 2026 · Metriken 1.13.0
Go
64MittelGesundheitsindex
TomTonic/extract-sbom
Sandboxed SBOM extraction from arbitrary artifacts. Outputs traceability records and CycloneDX JSON for automation, auditability, and supply chain security.
Go★ 221. Juli 2026
BSD-3-Clause21. Juli 2026 · Metriken 1.13.0
PyPI
64MittelGesundheitsindex
b7n0de/proofbundle
Offline cryptographic receipts for AI evaluation results — Ed25519 + RFC 6962 Merkle + optional SD-JWT. Integrity, not truth
Python★ 2↓ 6.574/Monat23. Juli 2026
MIT23. Juli 2026 · Metriken 1.13.0
PyPI · npm
62MittelGesundheitsindex
PrismorSec/prismor
Runtime Firewall for AI agents which catches the rogue tool call before it runs. Dangerous commands, secret leaks, prompt injection. For Claude Code, Codex and framework SDKs
Python · HTML★ 240↓ 6.171/Monat19. Juli 2026
Apache-2.019. Juli 2026 · Metriken 1.13.0
Go
61MittelGesundheitsindex
optimuslabs-io/grokpatrol
Open-source, offline forensic scanner CLI tool designed to detect evidence of git repo collection or upload by the Grok Build CLI to xAI infrastructure.
Go★ 1218. Juli 2026
Apache-2.018. Juli 2026 · Metriken 1.13.0
Go · npm
60MittelGesundheitsindex
codeswhat/lookout
Security-first remote Docker agent — authenticated Docker API proxy with outbound edge mode, Ed25519 per-request auth, and a cosign-signed, scratch-based supply chain. Drydock-native + generic REST.
Go · TypeScript★ 316. Juli 2026
Eigene Lizenz16. Juli 2026 · Metriken 1.13.0
npm
59MittelGesundheitsindex
starloghq/index
Vet a package before your AI coding agent uses it — authoritative facts (CVEs, license, maintenance) via an MCP server + CLI. Local, no account.
TypeScript★ 7↓ 2.182/Monat15. Juli 2026
Eigene Lizenz15. Juli 2026 · Metriken 1.13.0
Go
58MittelGesundheitsindex
famclaw/honeybadger
Security scanner for AI agent skills and MCP servers. Detects secrets, CVEs, supply chain attacks, and prompt injection in SKILL.md files before they're installed. Pre-install gate for Claude Code, OpenClaw, PicoClaw, NanoBot, FamClaw, and CI/CD pipelines. Single Go binary, MIT licensed.
Go★ 317. Juli 2026
MIT17. Juli 2026 · Metriken 1.13.0
Go
56MittelGesundheitsindex
Goryudyuma/gomod-cooldown
Delay newly available Go module versions during dependency updates with a temporary local GOPROXY.
Go★ 015. Juli 2026
MIT15. Juli 2026 · Metriken 1.13.0
Go
54MittelGesundheitsindex
jitpass/jit
jit is an open-source CLI that finds the plaintext secrets scattered across a Mac and converts them into just-in-time, Touch-ID-gated credentials, without breaking anything that reads them.
Go★ 215. Juli 2026
Eigene Lizenz15. Juli 2026 · Metriken 1.13.0
Go
54MittelGesundheitsindex
sairintechnologycom/pkgsafe
Supply-chain firewall for AI coding agents and developers — checks npm/PyPI packages against OSV advisories, typosquat & lifecycle-script heuristics, and your policy before install. Local-first, MCP-native.
Go★ 015. Juli 2026
MIT15. Juli 2026 · Metriken 1.13.0
PyPI
54MittelGesundheitsindex
zrk222/code-factory
Proof-first software factory for AI-assisted code: specs, adversarial gates, deterministic decisions, and reviewable receipts.
Python★ 0↓ 2.590/Monat17. Juli 2026
Eigene Lizenz17. Juli 2026 · Metriken 1.13.0
Go · npm
53MittelGesundheitsindex
undont/supplyscan
scan JavaScript lockfiles to detect supply chain vulnerabilities and known exploits
Go★ 022. Juli 2026
MIT22. Juli 2026 · Metriken 1.13.0